The vulnerability is present in all Windows versions of 7-Zip up to the current version of 21.07.
*When* they release a patch you can download the latest version here https://www.7-zip.org/
For now, you can protect yourself by deleting the file 7-zip.chm in your 7-Zip installation folder.
You can also switch to a different data compression software such as https://peazip.github.io/
Stay safe and be excellent to each other~
Post number #854545, ID: a62de6
|
> allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area
I can't even imagine myself doing this, like, what, why??
Thanks anyway.
Post number #854582, ID: 86bb31
|
Not the first time GUI operations under windows cause such vulnerabilities. This is why the GUI is often more restricted regarding rights management in most gnu/linux distros (while they are usually even totally absent in server distros, which is also why "windows server" is a meme for competent server admins).
Post number #854599, ID: 6197d7
|
I tried peazip but it was way slower to open than 7zip so I'll probably just not drag a 7z file into the help dialogue thanks
Post number #854646, ID: 89d755
|
The state of shills.
Post number #854652, ID: d57abd
|
i already uninstalled 7-zip, thanks pal
Post number #854661, ID: e9a94f
|
>>854582 I ironically find doing stuff in CLI easier. Perhaps I'm in denial as I open GUI only to browse web and launch a game off Steam.
Post number #854667, ID: a62de6
|
>>854661 next you're gonna say you use vim
Post number #854699, ID: 48cc5e
|
nano ftw
Post number #854795, ID: c9ce72
|
>>854667 is vim new i use arch meme? I didn't get, what can 7-zip do if it's not patched?
Post number #854863, ID: 65fa1e
|
>>854795 lol, reminds me of https://www.youtube.com/watch?v=kDiSWKaS3N0
Post number #854864, ID: 65fa1e
|
>>854545 meant to reply to this post
Post number #854906, ID: e9a94f
|
>>854667 heck no. I'm nano guy myself.
Post number #854911, ID: 9b05b6
|
praise the church of emacs
Total number of posts: 14,
last modified on:
Tue Jan 1 00:00:00 1650580239
| CVE-2022-29072
The vulnerability is present in all Windows versions of 7-Zip up to the current version of 21.07.
*When* they release a patch you can download the latest version here https://www.7-zip.org/
For now, you can protect yourself by deleting the file 7-zip.chm in your 7-Zip installation folder.
You can also switch to a different data compression software such as https://peazip.github.io/
Stay safe and be excellent to each other~